当前位置:网站首页>Cloud security daily 220623: the red hat database management system has found an arbitrary code execution vulnerability and needs to be upgraded as soon as possible
Cloud security daily 220623: the red hat database management system has found an arbitrary code execution vulnerability and needs to be upgraded as soon as possible
2022-06-23 18:50:00 【TechWeb】
6 month 22 Japan , Red hat has released a security update , Fixed the red hat relational database management system PostgreSQL Arbitrary code execution vulnerability found in . Here are the details of the vulnerability :
Vulnerability Details
source :https://access.redhat.com/errata/RHSA-2022:5162
CVE-2022-1552 CVSS score :8.8 severity : high
stay PostgreSQL A hole was found in . When a privileged user maintains another user's object , Incomplete efforts for safe operation will cause problems .Autovacuum、REINDEX、CREATE INDEX、REFRESH MATERIALIZED VIEW、CLUSTER and pg_amcheck The command is too late in the process or the relevant protection is not activated at all . This vulnerability allows an attacker to create non temporary objects in at least one mode , To execute any... As superuser SQL function .
Affected products and versions
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for IBM z Systems 7 s390x
Red Hat Enterprise Linux for Power, big endian 7 ppc64
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
Solution
RedHat Official by Red Hat Enterprise Linux 7 Provide postgresql to update , If postgresql Service is running , Automatically restart after installing this update .
For more information on how to apply this update , see also :
https://access.redhat.com/articles/11258
View more vulnerability information And upgrade, please visit the official website :
https://access.redhat.com/security/security-updates/#/security-advisories
边栏推荐
- 从零开发小程序和公众号【第一期】
- 2022年升降机司机考试题模拟考试平台操作
- [QT] multiple choice questions
- This year, Anhui master fund exploded
- When Jerry's serial port is set up, it prints garbled code, and the internal crystal oscillator is not calibrated [chapter]
- 矩阵分析笔记(三-1)
- Jerry's broadcast MP3 prompt sound function [chapter]
- Yapi installation
- Leetcode question brushing: hash table 03 (happy number)
- 【NOI2014】15.起床困難綜合症【二進制】
猜你喜欢
随机推荐
【翻译】一种减小运动伪影的新方法基于AS-LMS自适应滤波器的PPG信号
反直觉的三门问题,80%的人都会错?
Dataease template market officially released
Leetcode 1218. Longest definite difference subsequence (providing an idea)
Shell脚本编写
yapi安装
渗透测试基础,初识渗透测试
高级计网笔记(七)
GES图计算引擎HyG揭秘之图切分
Machine learning jobs
Shunted Self-Attention | 源于 PvT又高于PvT,解决小目标问题的ViT方法
高级计网笔记(五)
CV-图像分类
Leetcode question brushing: hash table 03 (happy number)
涂鸦智能通过聆讯:拟回归香港上市 腾讯是重要股东
Halcon knowledge: contour operator on region (1)
【NOI2014】15.起床困難綜合症【二進制】
Yaxiang spice listed on Shenzhen Stock Exchange: with a market value of 4billion, Dinglong Bohui and Yongyao investment are shareholders
可编程数据平面(论文阅读)
随机过程——马尔科夫链



![[QT] Chapter 3 and 4: window components and layout management](/img/e6/fb35566c227c4a8e564594d40e4eab.png)





